← Back

Duckdev

duckdev

3 CVEs • 2 products

Products (2)

Click to collapse
Toggle
404 To 301
404_to_301
Loggedin
loggedin

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Duckdev
1Loggedin
Apr 8, 2026
Oct 1, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.1....Show more
The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This is only exploitable when the leave a review notice is present.Show less
1Duckdev
1404 To 301
Apr 8, 2026
Jun 7, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible fo...Show more
The 404 to 301 plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the open_redirect & save_redirect functions in versions up to, and including, 3.0.7. This makes it possible for authenticated attackers to view, create and edit redirections.Show less
1Duckdev
1404 To 301
Nov 21, 2024
Aug 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.